News
NCC-CSIRT identifies two cyber attacks via Facebook, charging phones
Nasiru Yusuf
The Nigerian Communications Commission’s Cyber Security Incident Response Team (NCC-CSIRT) has independently identified two cyber vulnerabilities and advised Nigerian telecom consumers on the measures to be taken to get protected from the cyber-attacks.
KANO FOCUS reports that the CSIRT, in its first-ever security advisories less than three months after its creation, has solely identified the two cyber-attacks targeting the consumers and proffer solutions that can help telecom consumers from falling victims to the two cyber vulnerabilities.
This is contained in a statement sent to KANO FOCUS by Director, Public Affairs Dr. Ikechukwu Adinde on Friday.
The statement said the first is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations and it applies to all mobile phones.
The other is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.
According to CSIRT security Advisory 0001 released on January 26, 2022, with Juice Jacking, attackers have found a new way to gain unauthorized entry into unsuspecting mobile phone users devices when they charge their mobile phones at public charging stations.
Many public spaces, restaurants, malls and even in the public trains do offer complementary services to their customers in a bid to enhance customer services, one of which is providing charging ports or sockets.
However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.
“Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone.
“This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone. The attacker can even watch the victim in real time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone’s Global Positioning System (GPS) location.
“When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breach in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms. Symptoms of attack may include sudden spike in battery consumption, device operating slower than usual, apps taking a long time to load, and when they load they crash frequently and cause abnormal data usage,” the statement said.
It added that the NCC-CSIRT, however, proffered solutions to this attack to include using ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space; and not granting trust to portable devices prompt for USB data connection.
Other preventive measures against Juice Jacking, according to the statement include installing Antivirus and updating them to the latest definitions always; keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping mobile phone off when charging in public places; as well as ensuring use of one’s own charger, if one must charge in public.
On the other hand, the NCC-CSIRT Advisory 0001 of January 27, 2022, warns that Facebook for Android is vulnerable to a permission issue which gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone. The products affected include Versions 329.0.0.29.120 of Android OS.
With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.
However, to be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends to users to disable the feature from their device’s lock screen notification settings.
The NCC-CSIRT was inaugurated in October, 2021 to provide guidance and direction for the constituents in dealing with issues relating to the security of critical infrastructure in their possession, and periodically assess, review and collate the threat landscape, risks, and opportunities affecting the communications sector, in order to provide advice to relevant stakeholders in those regards.
As the telecoms-industry specific intervention, the objective of which aligns with the objective of the National Cybersecurity Policy and Strategy (NCPS) document published by the Office of the National Security Adviser (ONSA), the NCC-CSIRT ensures continuous improvement of processes and communication frameworks to guarantee secure and collaborative exchange of timely information while responding to cyber threats within the sector.
In recent times, NCC-CSIRT has raised series of cyber-vulnerability awareness based on security advisories it receives from the Nigerian Cybersecurity Emergency Response Team (ngCERT), which is the national body for the implementation of the NCPS objective. However, Juice Jacking and Facebook for Android Friend Acceptance Vulnerabilities are the two first-ever cyber vulnerabilities published by the NCC-CSIRT.
News
Cameroon telecom regulator visits NCC for benchmarking exercise
Nasiru Yusuf Ibrahim
The Director General of the Telecommunications Regulatory Board (ART) of the Republic of Cameroon, Philemon Zoo Zame, on Wednesday visited the headquarters of the [Nigerian Communications Commission (NCC) in Abuja for a benchmarking exercise aimed at strengthening regulatory collaboration and knowledge sharing between both countries.
KANO FOCUS reports that during the visit, the Cameroonian telecom regulator met with the Executive Vice Chairman and Chief Executive Officer of NCC, Aminu Maida.
A statement issued by Ayiabari A. Kigbara, Manager, Media Relations, Public Affairs Department of the NCC, said the engagement focused on exchanging ideas and best practices in telecommunications regulation, with emphasis on enhancing efficiency and development within the sector.
Headlines
Dangote Refinery maintains ex-depot price of PMS
Nasiru Yusuf Ibrahim
Dangote Petroleum Refinery and Petrochemicals Limited has announced that its ex-depot price of Premium Motor Spirit (PMS) remains unchanged, reaffirming its commitment to stability in Nigeria’s domestic energy market.
In a statement issued by Esan Sunday, Head of Media Relations, Branding and Communication, the company said sustaining the current price reflects its efforts to cushion the broader economy against external shocks. It noted that by absorbing prevailing cost pressures, the refinery is helping to moderate inflationary risks, promote energy affordability, and ensure uninterrupted fuel supply amid ongoing global uncertainties.
The company reiterated its dedication to the steady supply of high-quality petroleum products to the Nigerian market, while aligning with national objectives of price stability and energy security.
It also urged the public to rely solely on official communications from the refinery for accurate and up-to-date information regarding its operations and pricing.
Headlines
Tinubu congratulates Garo on appointment as Kano deputy governor
Nasiru Yusuf Ibrahim
President Bola Ahmed Tinubu has congratulated Alhaji Murtala Sule Garo on his emergence as the Deputy Governor of Kano State following his swearing-in on Tuesday.
KANO FOCUS reports that Garo was sworn in by Governor Abba Kabir Yusuf after being nominated to fill the vacancy created by the resignation of former deputy governor, Comrade Aminu Abdulsalam.
In a statement issued by his Special Adviser on Information and Strategy, Bayo Onanuga, the President described Garo’s appointment as a positive step toward strengthening unity within the All Progressives Congress (APC) in Kano State.
The President noted that the 48-year-old politician has held several public offices, including Chairman of Kabo Local Government Area and Commissioner for Local Government and Chieftaincy Affairs during the administration of former governor Abdullahi Umar Ganduje. He also served as the APC governorship running mate in the 2023 general elections.
Tinubu commended Governor Yusuf for the appointment, urging political stakeholders in the state to rally behind the administration to ensure stability and progress.
He also called on the new deputy governor to work closely with the governor in delivering effective leadership and accelerating development in Kano State.
The President wished Garo success in his new role.
